Liquid Network Hack: $320M BTC Stolen by Alleged White-Hat Hackers

Liquid Network Hack: $320M BTC Stolen by Alleged White-Hat Hackers

First seen 7 Sep 2026, 09:23 UTC Theblock.CoBitcoinmagazineTradingviewStraitstimesThecyberexpress+1 66.0

Article Content

Browse articles
ThreatCluster

The Liquid Network experienced a significant security breach where approximately 4,000 BTC, valued at $320 million, was withdrawn from its federation wallet. The attackers, described as purported white-hat hackers, exploited a vulnerability in the Liquid sidechain, specifically an inflation bug, to create and withdraw non-existent LBTC. Following the incident, Liquid Network paused all transactions and disabled bridge nodes to mitigate further risks. The hackers have communicated their intention to return 'most' of the stolen funds, contingent upon fixing the underlying vulnerability. However, the exact amount they plan to return remains unclear, and Liquid Network continues to classify the individuals involved as 'purported' white-hat hackers, indicating uncertainty about their true intentions. The incident has raised alarms about the security of crypto infrastructure and the potential risks to users holding Liquid Bitcoin (LBTC).

Key Points: • 4,000 BTC worth $320 million was stolen from Liquid Network's federation wallet. • Attackers exploited an inflation bug to withdraw non-existent LBTC, pausing network transactions. • Liquid Network is in discussions with the hackers, who demand a bug fix before returning funds.

Ask AI about this cluster

Timeline

2026-09-06
4,000 BTC withdrawn from Liquid Network
Purported white-hat hackers exploited an inflation bug to withdraw BTC from the federation wallet, prompting Liquid to halt transactions.
Bitcoinmagazine
2026-09-06
Liquid Network pauses transactions
In response to the hack, Liquid Network disabled bridge nodes and paused all new transactions to mitigate risks.
Tradingview
2026-09-07
Hackers communicate intentions
The hackers indicated they would return 'most' of the stolen BTC if the vulnerability was fixed, raising questions about their true motives.
Thecyberexpress